Skip to main content

databricks-access-audit

Databricks gives you no native way to answer "what can this identity access across all my workspaces?" — this tool does.

CI PyPI Python 3.9+ License: Apache 2.0

The Account Console shows you one workspace at a time. INFORMATION_SCHEMA shows you one metastore at a time. Neither resolves nested group memberships. Neither tells you whether a personal grant duplicates what the group already provides.

databricks-access-audit answers cross-workspace access questions in one command, across every workspace in your account at once.

Five modes

Mode Command Question it answers
Principal audit --principal "alice@company.com" What can this user / SP / group access across every workspace?
Group audit --group "data-engineers" What does this group access? Who has redundant personal grants?
Resource audit --resource "main" Who has access to this catalog / schema / table / workspace?
Compare --compare "alice@company.com" "bob@company.com" Which groups does Alice have that Bob doesn't?
Access provisioning --clone-from "alice@company.com" --to "bob@company.com" How do I give Bob the same access as Alice?

Install

pip install "databricks-access-audit[sdk]"

Add credentials to ~/.databrickscfg and run:

databricks-access-audit --principal "alice@company.com"
databricks-access-audit --group "data-engineers" --revoke-script
databricks-access-audit --resource "main" --output html > main_access.html

Documentation

https://lukaleet.github.io/databricks-access-audit

Tested environments

Developed and live-tested against Azure Databricks with Unity Catalog. AWS and GCP code paths exist but haven't been confirmed against real accounts yet.

If you run this on AWS, GCP, a large multi-workspace account, or with Okta/AWS SSO as your IdP — open an issue and let us know what works and what doesn't. Every environment report improves the tool.

Development

pip install -e ".[sdk,dev]"
pytest          # 570 tests, no real Databricks connection required
ruff check .

License

Apache 2.0 — see LICENSE.

Metadata

Release files for databricks-access-audit 0.25.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for databricks-access-audit 0.25.0
File Size Uploaded
databricks_access_audit-0.25.0.tar.gz 159.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for databricks-access-audit 0.25.0
File Interpreter ABI Platform
databricks_access_audit-0.25.0-py3-none-any.whl Python 3 none any Details

Total release size: 279.7 kB

Release files / databricks_access_audit-0.25.0.tar.gz

Download URL databricks_access_audit-0.25.0.tar.gz
Size 159.4 kB
Tags Source
SHA-256 checksum
How to use checksums
013f31aaba2e1c56b2ebfb38a3053dd7ef547b113f71a173df4b74f2bbfaec5f
BLAKE2b-256 checksum
How to use checksums
3560bd8084a0258ffea1fd84d7bed5dbcc6f661df94def768ccd03eee981c5f1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 15, 2026.

Transparency log

Release files / databricks_access_audit-0.25.0-py3-none-any.whl

Download URL databricks_access_audit-0.25.0-py3-none-any.whl
Size 120.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cdb06fcce52b052154d7215e97b8cd69d01a4e029983af5659f0ce77fb08f46f
BLAKE2b-256 checksum
How to use checksums
409022054b3ed0fed1a907d805a54ddf8f46602f7051e08ba78ca60924e09352
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on May 15, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.25.0 This release

2 release files

0.24.0

2 release files

0.23.0

2 release files

0.22.1

2 release files

0.22.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page